logo

Security alert: WSUS remote code execution vulnerability

ID: 171d3f5e-f94e-501e-83eb-78f1d68bac33

STIX ID: report--171d3f5e-f94e-501e-83eb-78f1d68bac33

Feed Name: Expel Blog

Threat Score
90/100

Date Published: 2025-10-24

Date Updated: 2026-04-27

Author: Aaron Walton

...
...

**CVE-2025-59287 (WSUS RCE) — Active exploitation observed; patch immediately.** A critical remote code execution vulnerability in Windows Server Update Service is being actively exploited against internet-exposed WSUS servers to run SYSTEM-level PowerShell commands that enumerate host and domain information and exfiltrate it (observed to webhook.site); organizations should patch WSUS instances promptly even if not believed to be internet-exposed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.